What Every Business Can Learn from the TfL Cyber Attack
- Delta Team

- Jul 1
- 3 min read
Guilty Pleas Serve as a Reminder: Cyber Attacks Can Happen to Anyone
Nearly two years after Transport for London (TfL) suffered one of the UK's most disruptive cyber attacks, the story returned to the headlines this month, June 2026, with two UK nationals pleading guilty to offences under the Computer Misuse Act, in connection with the attack.
While the criminal prosecutions are welcome, they do not undo the damage caused. The 2024 Transport for London (TfL) attack is a clear reminder that social engineering is often the gateway to sophisticated cyber attacks, with attackers believed to have gained access by manipulating help desk processes and compromising legitimate user credentials.
Once inside, they were able to move through TfL's environment, disrupting online services, exposing around 10 million customer records and contributing to an estimated £39 million in recovery costs.
It's a reminder that attackers don't always break in, they're often let in as a result of social engineering.
Here are four lessons every organisation should take from the incident.
1. Lock down privileged accounts
Administrative accounts are one of the first things attackers look for after gaining access. If they can compromise a privileged account, they can move around the network, access sensitive systems and potentially disable security controls.
Protect privileged accounts by:
Enforcing Multi-Factor Authentication (MFA).
Using dedicated administrator accounts.
Applying the principle of least privilege.
Regularly reviewing and removing unnecessary permissions.
A compromised user account shouldn't become a compromised business.
2. Train staff to recognise social engineering
The attackers targeting TfL are believed to have relied heavily on social engineering, manipulating people rather than exploiting technical vulnerabilities. Increasingly, attackers are targeting not only an organisation's employees, but also managed service providers (MSPs), IT support teams and help desks, exploiting trusted relationships to gain access.
Regular security awareness training should ensure employees and those with privileged access understand how to:
Recognise phishing emails and fake login pages.
Challenge unexpected requests for passwords, MFA codes or account resets.
Verify the identity of callers claiming to be IT support or trusted third parties.
Follow robust SOP’s or identity verification procedures before granting access or resetting credentials of user accounts.
Report suspicious activity immediately.
Effective awareness training, supported by strong identity verification processes, can prevent a social engineering attempt from becoming a major security incident.
3. Plan for systems going offline
The attack disrupted customer-facing services, delayed operations and forced TfL to recover systems over an extended period.
Ask yourself:
Could your business continue operating if key systems became unavailable tomorrow?
Are critical procedures documented offline?
Has your incident response plan been tested?
Business continuity isn't just about backups, it's about keeping your organisation running when technology fails.
4. Build strong foundations with Cyber Essentials
Many successful cyber attacks exploit common weaknesses in cyber hygiene rather than advanced hacking techniques.
Cyber Essentials helps organisations address these fundamentals through controls covering:
User access management
Secure configuration
Security updates
Malware protection
Firewalls
Cyber Essentials Plus goes one step further by independently verifying those controls through technical testing, providing additional assurance that they are working as intended.
Prevention starts before the attack
The TfL incident demonstrates that a single compromised account can have far-reaching consequences. Strong identity controls, informed employees, tested business continuity plans and recognised security standards all play a vital role in reducing cyber risk.
No organisation can eliminate the threat entirely, but every organisation can make itself a far more difficult target.
Need help assessing your cyber resilience?
Whether you're working towards Cyber Essentials, looking to strengthen your security controls or want independent advice on improving your cyber resilience, the team at Delta Cyber Security is here to help. Get in touch to discuss how we can support your business.



